Which Audit Type Compares Security Policies to External Regulations?

The Chief Information Security Officer (CISO) at a large company would like to gain an understanding of how the company's security policies compare to the requirements imposed by external regulators. Which of the following should the CISO use?

  1. Penetration test
  2. Internal audit Source Reference Answer
  3. Attestation
  4. External examination

Community Votes

B
62%
D
38%

62% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the logical sequence of compliance activities, trapping candidates who fall for the 'external regulators = external examination' keyword match instead of recognizing that internal audits are the standard, cost-effective method for initial policy-to-regulation alignment.

This question evaluates the distinction between internal audits and external examinations in regulatory compliance workflows. The community consensus strongly favors internal audit, highlighting that organizations conduct self-assessments first to identify gaps between current policies and external regulatory mandates before pursuing formal third-party validation.

Candidates frequently choose D (External examination) because they over-index on the word 'external,' failing to read the prompt's emphasis on 'gaining an understanding.' In reality, external examinations are formal, resource-intensive processes used for final certification or regulatory submission, not preliminary gap analysis.

Community Discussion (18 comments)

01a4c2e 👍 7 Selected: B
Ty13 2 weeks, 2 days ago B. Internal Audit I know people want to select D because... it sounds right. External audit to compare against external regulations. But there's a part being overlooked: 'would like to gain an understanding'. Which you don't NEED a third party to confirm, because the company already KNOWS those regulations. But you WOULD need an external audit if there was a large breach and the regulatory agencies wanted to know how it happened. What is being asked, effectively, is "Can an internal audit team verify that we meet external regulations?"
Rackup 👍 1 Selected: D
Answer: D. External examination Explanation: An external examination is the best approach for the CISO to gain an understanding of how the company's security policies compare to the requirements imposed by external regulators. This process typically involves an external party, such as a third-party auditor or regulatory body, reviewing the company's security policies and controls to ensure they align with industry regulations and standards. While internal audits (B) assess the company's internal controls and practices, external examinations provide an unbiased review from an external perspective, which is essential for understanding compliance with external regulatory requirements.
ijia_Ai0823 👍 1 Selected: B
In my opinion, it's Internal audit. It's more likely to be a sequential things (Based on an ISO-9001 external audit I experienced before). A company usually do an internal audit before proceeding to an external audit, because external audit must have a authorized third-party auditors and can be quite costly to be certified that your company is qualified by the auditors. In most cases, the auditors may conclude some corrective actions(like CAR) that need your company to finish. After the correction report is submitted and validated by the auditors, your company can receive the approved certification.
Suga_1 👍 1
The correct answer is: C. Attestation. Explanation: Attestation: This involves an independent third party verifying that the company's security policies, processes, or systems meet the requirements imposed by external regulations. Attestations are often used to demonstrate compliance with regulatory frameworks and standards such as SOC 2, ISO 27001, or GDPR.
laternak26 👍 2 Selected: B
An internal audit is a comprehensive evaluation of a company's operations, processes, and policies to ensure they are compliant with internal standards as well as external regulations. In the context of comparing the company's security policies to external regulatory requirements, an internal audit would be the most appropriate tool. It involves reviewing and assessing the security measures and procedures in place and determining how well they align with legal and regulatory requirements, ensuring that the company meets compliance standards. Why not D. External examination: An external examination is typically performed by third-party auditors or regulators to assess compliance with external standards and regulations. While it can provide valuable insights into regulatory adherence, it is not the best tool for an internal review by the CISO. An internal audit allows the CISO to assess the company's own security policies and their alignment with external regulations before seeking an external review.
ProudFather 👍 2 Selected: D
D. External examination An external examination by a qualified third-party auditor can provide an objective assessment of the company's security practices against industry standards and regulatory requirements. This can help the CISO identify any gaps or weaknesses in the company's security posture and take corrective action. The other options are not as suitable:
e2ba0ff 👍 2 Selected: B
vendor's self-assessment of practices against industry or organizational requirement
Murtuza 👍 2 Selected: D
Between the two options, D. External examination is the most suitable for understanding how the company’s security policies compare to external regulatory requirements. An external examination involves an independent review by an external party, providing an objective assessment of the company’s compliance with regulatory standards. This ensures that the evaluation is unbiased and thorough, which is crucial for regulatory compliance.
nillie 👍 2 Selected: B
The CISO should use: B. Internal audit An internal audit is a structured assessment of the company's security policies, processes, and controls to ensure they meet both internal standards and external regulatory requirements. This will help the CISO understand how well the company's security policies align with the requirements imposed by regulators.
Ty13 👍 2 Selected: B
B. Internal Audit I know people want to select D because... it sounds right. External audit to compare against external regulations. But there's a part being overlooked: 'would like to gain an understanding'. Which you don't NEED a third party to confirm, because the company already KNOWS those regulations. But you WOULD need an external audit if there was a large breach and the regulatory agencies wanted to know how it happened. What is being asked, effectively, is "Can an internal audit team verify that we meet external regulations?"
RIDA_007 👍 1 Selected: D
An external examination (also known as an external audit or external review)
NONS3c 👍 1 Selected: B
even GPT Said
Cyber_Texas 👍 1
D external examination is best here
myazureexams 👍 4 Selected: D
It is D period. And for the exam, make the association "External with External" DONE
Glacier88 👍 1 Selected: D
External examination: An external examination, conducted by an independent third party, can provide an objective assessment of the company's security policies and practices against external regulatory requirements. This can help the CISO identify any gaps or areas for improvement. Penetration test: While penetration tests can identify vulnerabilities in the company's security infrastructure, they don't directly assess compliance with external regulations. Internal audit: Internal audits can assess the company's adherence to internal policies and procedures, but they might not provide a comprehensive view of compliance with external regulations. Attestation: Attestation is a formal process of providing assurance about a specific claim or assertion. While it might involve compliance with regulations, it doesn't necessarily provide a full assessment of the company's security policies and practices.
baronvon 👍 3 Selected: B
B. Internal audit An internal audit allows the CISO to assess how the company's security policies align with the requirements imposed by external regulators. This process involves reviewing and evaluating the company's policies, procedures, and controls to ensure compliance with regulatory standards.
Dlove 👍 1 Selected: D
D. External Examination An external examination involves a review or assessment conducted by an independent third party, often to evaluate how an organization's policies, procedures, and practices align with regulatory requirements or industry standards. This process is crucial for identifying gaps between the company’s internal security policies and the requirements imposed by external regulators. It provides the CISO with an unbiased understanding of the organization’s compliance status.
a4e15bd 👍 4
B. Internal Audit An internal audit involves a thorough review of the company's policies and procedures to ensure they meet the regulatory requirements and industry standards.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Compliance Assessment Hierarchy

When evaluating how organizational security policies align with external regulatory requirements (such as HIPAA, GDPR, PCI-DSS, or SOX), the first step is almost always a structured internal audit. An internal audit is conducted by the organization’s own compliance, risk, or IT teams to systematically review controls, document findings, and identify gaps against both internal standards and external mandates. As noted by multiple high-voted community members, the phrase 'would like to gain an understanding' signals a need for gap analysis and self-assessment, which does not require third-party involvement.

Why External Examination Is a Distractor

Option D (External examination) refers to a formal, independent review conducted by qualified third parties (e.g., certified auditors or regulatory bodies). While highly valuable, these are typically reserved for final compliance certification, post-breach investigations, or contractual obligations—not for initial policy alignment studies. Relying on external exams prematurely wastes budget and time. The community correctly points out that you only escalate to an external examiner after internal controls have been mapped, tested, and remediated.

Eliminating Technical and Formal Alternatives

  • Penetration test (A) focuses on identifying technical vulnerabilities in systems and networks through simulated attacks. It does not evaluate policy documentation, procedural compliance, or regulatory alignment.
  • Attestation (C) is a formal written declaration by a third party confirming that specific controls meet defined standards. It is the output or deliverable of an audit process, not the assessment tool itself.

Community Consensus & Practical Application

Multiple experienced candidates emphasize that internal audits serve as the foundational step in the GRC lifecycle. They allow the CISO to benchmark current practices, prioritize remediation efforts, and prepare evidence packages before engaging external validators. This sequential approach aligns with industry best practices and CompTIA’s emphasis on risk management efficiency and fiscal responsibility.

Official Reference

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide